5
CVSSv2

CVE-2002-1559

Published: 31/03/2003 Updated: 05/09/2008
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Directory traversal vulnerability in ion-p.exe (aka ion-p) allows remote malicious users to read arbitrary files via (1) C: (drive letter) or (2) .. (dot-dot) sequences in the page parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

research systems inc. ion script 1.4

Exploits

source: wwwsecurityfocuscom/bid/6091/info A vulnerability has been discovered in ION Script By sending a malicious HTTP request to a webserver running the vulnerable ION Script package, it is possible for a remote attacker to disclose arbitrary webserver readable files As webservers are often run with high privileges, it may be possibl ...